How To

Ideas from Security Awareness Survey Respondents

Practical steps to establishing employee security awareness

By Lew McCreary

November 01, 2006CSO

• Live events help lessons sink in. Hold monthly brown-bag awareness lunches for departments or remote facilities.

• Stay in people's faces: Publish a monthly newsletter on current security threats and issues. Report security metrics, both good and bad.

• Find ways of expressing the cost-avoidance benefits of improved security. For example, put a dollar amount on fewer incidents and shorter recovery times.

• Have the CEO and other top executives attend security Q&A meetings (and have them take some questions). Make sure important security memos go out under the CEO's name.

• Have direct contact with employees. Manage by walking around!

• When new threats emerge, act quickly to inform the enterprise. Demystify but don't scare.

• Make awareness initiatives vivid so that they are felt on a personal gut level by individual employees.

• Engage in multimedia education: posters, online tutorials, live events, podcasts.

• Focus on high-value awareness initiatives: loss-prevention in retail businesses, counter-

competitive-intelligence strategies in research-rich environments, data privacy in financial institutions.

*–L.M.

Other stories by Lew McCreary

$firstKeyword

RESOURCE CENTER
Loading...
VIRTUAL CONFERENCE
Security Directions: A Virtual Conference

Security Directions Available On Demand Sept. 30 - Dec. 30

Join us for a virtual event with candid, expert information on top security challenges and issues - all from the comfort of your desktop.

» Register Now

WEBCAST
Protecting PII: How to Work with IT to Manage Risk

Compuware Understand the critical nature of the test data privacy problem and get tips on how to work with IT to implement a test data privacy program.

» View this Webcast

Featured Sponsors